CVE-2026-39815

8.8

Fortinet · FortiDDoS-F

A SQL injection vulnerability in Fortinet FortiDDoS-F versions 7.2.1 through 7.2.2 allows authenticated attackers to execute unauthorized commands via crafted HTTP requests.

Executive summary

A critical SQL injection vulnerability in Fortinet FortiDDoS-F allows authenticated attackers to execute unauthorized commands, posing a significant risk to system integrity and data confidentiality.

Vulnerability

This vulnerability is a SQL injection (CWE-89) flaw occurring when the application fails to properly neutralize special elements in SQL commands. An attacker with low-level privileges can trigger this flaw by sending crafted HTTP requests to the vulnerable interface, resulting in unauthorized command execution.

Business impact

The ability for an attacker to execute arbitrary SQL commands provides a path to full system compromise, data exfiltration, or complete loss of service availability. Given the CVSS score of 8.8, this vulnerability represents a high-severity threat that could lead to unauthorized access to sensitive backend databases and administrative functions within the FortiDDoS appliance.

Remediation

Immediate Action: Upgrade to FortiDDoS-F version 7.2.3 or above immediately to remediate the underlying code vulnerability.

Proactive Monitoring: Review database access logs for anomalous, complex, or malformed query patterns that deviate from standard operational traffic.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to inspect incoming HTTP requests for SQL injection signatures, providing a temporary layer of protection while systems are staged for patching.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Fortinet administrators must prioritize the update to version 7.2.3 to eliminate this SQL injection risk. Given the potential for unauthorized command execution, failure to patch could lead to a total compromise of the affected security appliance. Verify all configurations post-update and ensure that least-privilege principles are applied to all accounts with access to the management interface.

More Fortinet CVEs

Sources